• DocumentCode
    932494
  • Title

    PacketScore: a statistics-based packet filtering scheme against distributed denial-of-service attacks

  • Author

    Kim, Yoohwan ; Lau, Wing Cheong ; Chuah, Mooi Choo ; Chao, H. Jonathan

  • Author_Institution
    Sch. of Comput. Sci., Nevada Univ., Las Vegas, NV
  • Volume
    3
  • Issue
    2
  • fYear
    2006
  • Firstpage
    141
  • Lastpage
    155
  • Abstract
    Distributed denial-of-service (DDoS) attacks are a critical threat to the Internet. This paper introduces a DDoS defense scheme that supports automated online attack characterizations and accurate attack packet discarding based on statistical processing. The key idea is to prioritize a packet based on a score which estimates its legitimacy given the attribute values it carries. Once the score of a packet is computed, this scheme performs score-based selective packet discarding where the dropping threshold is dynamically adjusted based on the score distribution of recent incoming packets and the current level of system overload. This paper describes the design and evaluation of automated attack characterizations, selective packet discarding, and an overload control process. Special considerations are made to ensure that the scheme is amenable to high-speed hardware implementation through scorebook generation and pipeline processing. A simulation study indicates that packetscore is very effective in blocking several different attack types under many different conditions
  • Keywords
    Internet; computer crime; packet switching; performance evaluation; pipeline processing; statistics; telecommunication security; Internet; PacketScore; attack packet discarding; automated online attack characterizations; distributed denial-of-service attacks; network level security; network monitoring; performance evaluation; pipeline processing; score-based selective packet discarding; scorebook generation; statistics-based packet filtering; system overload control; Chaos; Computer crime; Computer science; Computer security; IP networks; Information filtering; Information filters; Internet; Protection; Telecommunication traffic; Network level security and protection; network monitoring; performance evaluation; security; simulation.; traffic analysis;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2006.25
  • Filename
    1632008